CVE Tools

CVE-2025-3935

ScreenConnect Exposure to ASP.NET ViewState Code Injection

Published: Apr 25, 2025Updated: Oct 24, 2025 Sources: CVE List NVD BDUCWE-502

Description

ScreenConnect versions 25.2.3 and earlier versions may be susceptible to a ViewState code injection attack. ASP.NET Web Forms use ViewState to preserve page and control state, with data encoded using Base64 protected by machine keys.  It is important to note that to obtain these machine keys, privileged system level access must be obtained. If these machine keys are compromised, attackers could create and send a malicious ViewState to the website, potentially leading to remote code execution on the server.  The risk does not originate from a vulnerability introduced by ScreenConnect, but from platform level behavior.  This had no direct impact to ScreenConnect Client. ScreenConnect 2025.4 patch disables ViewState and removes any dependency on it.

In plain language

AI Act now

CVE-2025-3935 is a ScreenConnect weakness where, after stealing internal encryption keys from the server, an attacker can send a malicious message to take over the server; this is actively exploited and a typical small business using ScreenConnect should treat it as urgent.

Executive summary

CVE-2025-3935 (CWE-502) is an ASP.NET ViewState code injection issue in ScreenConnect that enables remote code execution on the server when an attacker has compromised the machine-level encryption keys and then sends a crafted ViewState payload over the network; it is listed in CISA KEV and is actively exploited.

If affected, business impact
Full server takeoverRansomware riskCustomer data exposureService disruption

What to do now

  1. Check your ScreenConnect version and whether it is up to date (the last affected version is 25.2.3 or earlier).
  2. Upgrade ScreenConnect to 25.2.4 (or the latest available stable version) as the confirmed fix.
  3. If you can’t upgrade immediately, follow ConnectWise vendor mitigations from their security bulletin/advisory links and/or temporarily discontinue use until mitigations are available.
  4. Verify the upgrade completed successfully and that the service is restarted, then review access logs for suspicious ScreenConnect traffic around the same time as any alerts.
Patch / advisory Usually a quick update

CVSS Vector Breakdown

AV:NAC:HPR:NUI:NS:UC:HI:HA:H
Exploitability
AV:NAttack Vector
Network
AC:HAttack Complexity
High
PR:NPrivileges Required
None
UI:NUser Interaction
None
Scope
S:UScope
Unchanged
Impact
C:HConfidentiality
High
I:HIntegrity
High
A:HAvailability
High

Weaknesses

Affected Products

and 1 more affected products View all →

Exploitability

CISA Known Exploited Vulnerability
Added to KEV:Jun 2, 2025
Remediation due:Jun 23, 2025

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Official Patch Available

Attack Graph

Products CVE Techniques Tactics

Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.

MITRE ATT&CK

3 techniques
Execution
Initial Access
View detailed technique mapping

References

2

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2025-3935 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store